.. / Diskshadow.exe
Star

Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).


Paths:


Resources:
https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/

Acknowledgement:
Jimmy - @bohops


Detection:
Child process from diskshadow.exe
Diskshadow reading input from file



Dump

Execute commands using diskshadow.exe from a prepared diskshadow script.
diskshadow.exe /s c:\test\diskshadow.txt
Usecase:Use diskshadow to exfiltrate data from VSS such as NTDS.dit
Privileges required:User
OS:Windows server
Mitre:T1218



Execute

Execute commands using diskshadow.exe to spawn child process
diskshadow> exec calc.exe
Usecase:Use diskshadow to bypass defensive counter measures
Privileges required:User
OS:Windows server
Mitre:T1003